package com.base.system.config.security;

import com.base.system.base.http.origin.AccessAllowOrigin;
import com.base.system.enums.HttpStatus;
import org.springframework.security.access.AccessDeniedException;
import org.springframework.security.web.access.AccessDeniedHandler;
import org.springframework.stereotype.Component;

import javax.servlet.ServletException;
import javax.servlet.http.HttpServletRequest;
import javax.servlet.http.HttpServletResponse;
import java.io.IOException;

/**
 * 自定义权限不足拦截器
 */
@Component
public class AuthenticationAccessDeniedHandler implements AccessDeniedHandler {
    @Override
    public void handle(HttpServletRequest httpServletRequest, HttpServletResponse resp, AccessDeniedException e) throws IOException, ServletException {
        AccessAllowOrigin accessAllowOrigin = new AccessAllowOrigin(httpServletRequest, resp);
        accessAllowOrigin.allowOrigin();
        accessAllowOrigin.write(HttpStatus.forbidden, "权限不足，请联系管理员!");
    }
}
